SAS Web Infrastructure Platform applications, including SAS Logon Manager, might be vulnerable to Cross-Site Request Forgery (CSRF) attacks.
CVSS Score: 6.0
Click the Hot Fix tab in this note to access the hot fix for this issue.
Important Notes:
The application of this hot fix provides a filter for protection against CSRF in the SAS® installation. The filter is disabled by default to allow you the opportunity to configure it before it is enabled, which avoids potential user impact upon enablement.
With this protection enabled, requests that do not originate from sites that belong to a whitelist are rejected. By default, the implications of this change are that the SAS installation is secure against browser-based CSRF attacks and applications that are external to the SAS installation cannot link to SAS web applications. If you link to a SAS application from a company intranet or a portal page that is not hosted in the SAS installation, you encounter access denied messages when you click those links.
There are many legitimate cases where it is necessary to link to SAS web applications. For such cases, you can add a site that contains a link to a SAS web application to the SAS CSRF whitelist, as follows:
Including a trailing slash at the end of each value is important because omitting the slash means that sites can use a prefix attack to bypass the protections. Be sure to include port numbers in the value if the whitelisted site uses ports other than the standard 80 or 443 for HTTP and HTTPS, respectively. You can also restrict a value to an application on the whitelisted site by including the application’s path in the value, for example, http://my-intranet.example.com/my-application-path/.
To enable CSRF checking and enforcement, set the sas.web.csrf.referers.performCheck property to true in the advanced properties for SAS Application Infrastructure.
After changing any of the properties that are discussed above, you must restart the SAS® Web Application Server in order for the changes to take effect.
As an option, you can choose to set CSRF properties on individual web applications in your SAS installation by using Configuration Manager. After you make any changes in Configuration Manager, you need to restart all of the web application servers in your SAS middle tier in order for the settings to take effect.
For more details about the CSRF software attack, see the Open Web Application Security Project's (OWASP) Cross-Site Request Forgery (CSRF) page.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Web Infrastructure Platform | Solaris for x64 | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 |
Linux for x64 | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
HP-UX IPF | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
64-bit Enabled Solaris | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
64-bit Enabled HP-UX | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
64-bit Enabled AIX | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
Windows Vista for x64 | 9.2_M1 | 9.2 TS2M0 | ||||
Windows Vista | 9.2_M1 | 9.2 TS2M0 | ||||
Microsoft Windows XP Professional | 9.2_M1 | 9.2 TS2M0 | ||||
Microsoft Windows Server 2008 for x64 | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
Microsoft Windows Server 2008 R2 | 9.2_M1 | 9.4_M3 | 9.2 TS2M0 | 9.4 TS1M3 | ||
Microsoft Windows Server 2003 for x64 | 9.2_M1 | 9.2 TS2M0 | ||||
Microsoft Windows Server 2003 Standard Edition | 9.2_M1 | 9.2 TS2M0 | ||||
Microsoft Windows Server 2003 Enterprise Edition | 9.2_M1 | 9.2 TS2M0 | ||||
Microsoft Windows Server 2003 Datacenter Edition | 9.2_M1 | 9.2 TS2M0 |
A fix for this issue for SAS Portal and Portlets 4.31_M2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/L11.html#55044A fix for this issue for Search Interface to SAS Content 3.4 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/U28.html#55044A fix for this issue for Search Interface to SAS Content 3.5 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/T87.html#55044A fix for this issue for SAS Visual Analytics 7.2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/T94.html#55044A fix for this issue for SAS Visual Analytics 7.1 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/S19.html#55044A fix for this issue for SAS Middle Tier 9.4_M2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/R75.html#55044A fix for this issue for SAS Management Console 9.4_M2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/R76.html#55044A fix for this issue for SAS Middle Tier 9.3_M2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/I14.html#55044Type: | Problem Note |
Priority: | alert |
Date Modified: | 2015-05-06 12:08:28 |
Date Created: | 2015-01-22 08:56:52 |